Home · Security
Security and data sovereignty
Digital twins are institutional assets. The rules are simple and they never change: the institution owns every right to its data, access is private by default, and everything can leave the platform in open formats whenever you decide.
The HUB runs on SweetHive, an infrastructure built for regulated, high-trust environments. The answer to the question every institution asks first, where does the data go, is structural, not a promise.
Every scan, model and derivative belongs to the collection's owner. We operate the platform; we acquire no rights, ever.
Access follows roles: conservators, curators and partners see only what they should. Nothing becomes public without an explicit decision, and sensitive works can stay visible to a restricted circle only.
European collections on EU infrastructure, US collections on US infrastructure: every country can have its own hosting, encrypted in transit and at rest, with residency guaranteed per region.
Each file's fingerprint is notarized on a public blockchain at capture: provenance and integrity you can show an insurer or a court.
Storage and processing can be pinned to the institution's own hardware, inside its own perimeter: the computing comes to the data, the data never leaves.
Dedicated deployments for public bodies: sovereign hosting, custom retention, and compliance with national heritage systems from day one. The connector layer →
Heavy computing should not be a privilege. The HUB routes every workload across three tiers, by sensitivity, latency and cost:
Sensitive, confidential work runs on machines inside the institution. Scope is enforced down to the hardware.
Non-sensitive heavy work, meshes, tiles, renders, bursts to a distributed network of independent nodes. Capacity grows with the network and unit costs keep falling: high-end computing stays accessible to small museums too.
Per workload: private only, network allowed, or automatic. The default keeps sensitive work at home. The full security model →
Open formats and export always available: the twins can leave the HUB at any time, complete and readable. No lock-in by design.
FAQ
The institution, always. Every scan, model and derivative belongs to the museum or to the owner of the artwork. AerariumChain operates the infrastructure and never acquires rights over the collection.
In the region the institution chooses: EU collections on EU infrastructure, US collections on US infrastructure, and every country can have its own hosting. Data is encrypted in transit and at rest, and institutions with stricter requirements can pin storage and processing to their own hardware.
Yes. Everything is private by default: people see only what their role allows, and nothing is published without an explicit decision. Sensitive works can remain visible to a restricted group only.
Yes. Full export in open formats, METS packages, meshes, TIFF pyramids, is always available. No lock-in, by contract and by design.
With dedicated deployments: sovereign or on-premise hosting, custom retention policies and compliance with national heritage regulations.
Every file's fingerprint is written to a public blockchain the moment it is captured. Integrity and provenance can be verified at any time, by anyone you authorize.
Detailed security documentation is available to institutions on request.